Re: Uploading Word documents, PDFs, PNG files etc

From: Sebastian Tennant
Subject: Re: Uploading Word documents, PDFs, PNG files etc
Date: Thu, 14 May 2009 12:49:14 +0000
Quoth Keith Wright <address@hidden>:
>> > Restricting regexps to actual text is fine... until
>> > you need to grep binary data, or, as in this case,
>> > a combination of text and binary data.
>> > in cgi.scm that extracted the uploaded (possibly
>> > binary) file, because the pattern identifying the
>> > beginning of the file in the raw data string is
>> > simple ("\n\r\n\r") -
>> No, this sounds somehow broken.  If I remember correctly,
>> binary mime-parts should have a ConentLength header
>> so you can skip over them. If ContentLength is absent,
>> then the part should bee ascii-encoded (e.g. base64)
>> yeah, grapping large blocks of ascii sucks, which is
>> why the ContetnLength should be used.
>> -- linas
> If the spec says a length indication followed by
> a fixed length of arbitrary binary data, then it
> is not just sucky, but incorrect to apply either
> grep or regexp to the binary.  It will seem to
> work until it hits a binary data that "by
> accident" contains the string you are looking
> for.
> The only correct algorithm is to make a preliminary
> pass to somehow remove the binary data and
> pseudo-concatenate the remaining strings.

Multipart/form-data comes with a Content-Length header that describes
the length of any and all parts combined, making it possible to extract
a string that looks like this:

 Content-Disposition: form-data; name=\"TABLE\"\x0d
 Content-Disposition: form-data; name=\"File-Upload\"; 
 Content-Type: text/plain\x0d
 Content-Disposition: form-data; name=\"Button\"\x0d

The boundary can be obtained from the Content-Type header and the above
string can then be broken into parts but how can one extract the name,
filename, type and value of each part without using regexps?

cgi.scm currently uses the following patterns and I can't think of an
alternative way of doing it:

 (let ((name-rx     (make-regexp "name=\"([^\"]*)\""))
       (filename-rx (make-regexp "filename=\"*([^\"\r]*)\"*"))
       (type-rx     (make-regexp "Content-Type: ([^\r]*)\r\n" regexp/icase))
       (value-rx    (make-regexp "\r\n\r\n")))

